Trust Center

Proof, not promises. How Emberalis protects the most sensitive data you own.

Zero-knowledge encryption

Everything in your vault, from passwords to files to farewell messages, is encrypted in your browser before it ever reaches us. The keys are derived from your password on your device and never leave it. In plain terms: we cannot read your data, even if we wanted to, even if we were compelled to, even if our servers were breached.

  • AES-256-GCM encryption per vault item and per file
  • Argon2id key derivation from your master password, on your device
  • RSA-OAEP key escrow so emergency contacts can be granted access without us
  • The server stores only encrypted blobs and public keys

Want the full technical design (key hierarchy, escrow model, algorithm choices)? Ask us and we will share the architecture documentation.

Subprocessors

These are the vendors we rely on, what they do for us, and where your data is processed. Vault content reaches none of them in readable form.

VendorPurposeDataRegionTransfer basis
Appwrite CloudBackend platform: database, authentication, file storageAccount data, encrypted vault items and files (zero-knowledge: content is encrypted client-side)United States (NYC region)EU Standard Contractual Clauses (SCCs)
VercelApplication hosting, edge network and cron schedulingRequest metadata (IP addresses, logs)Global edge, primary EU/USEU-US Data Privacy Framework / SCCs
StripePayments and subscription billingName, email, payment details, billing historyUnited States / European UnionEU-US Data Privacy Framework
TwilioSMS and WhatsApp delivery (phone verification, check-ins)Phone numbers, message delivery metadataUnited StatesEU-US Data Privacy Framework
ResendTransactional email (verification, check-ins, emergency alerts)Email addresses, email content and delivery metadataUnited StatesEU Standard Contractual Clauses (SCCs)
LoopsMarketing and lifecycle emailEmail address, name, product usage milestonesUnited StatesEU Standard Contractual Clauses (SCCs)
SentryError tracking and cron monitoringError reports and diagnostics (PII scrubbed before sending)United StatesEU-US Data Privacy Framework
PostHogProduct analytics (event tracking only, no feature flags)Pseudonymous usage events, device metadataEuropean Union (EU Cloud)Processed within the EU
LaunchDarklyFeature flagsUser identifier for flag targetingUnited StatesEU-US Data Privacy Framework
ArcjetRate limiting, bot detection and disposable-email blockingIP addresses, request metadata, email addresses (validation)United StatesEU Standard Contractual Clauses (SCCs)

Uptime & monitoring

Independent infrastructure

Hosting (Vercel) and backend (Appwrite Cloud) publish their own status pages: vercel-status.com and status.appwrite.online.

Cron monitoring

The check-in escalation cron is monitored with Sentry Cron Monitoring: a silently missed run pages us. The deadman's switch itself has a deadman's switch.

Error tracking

Errors are tracked in Sentry with PII scrubbing applied before anything leaves our servers.

Compliance & privacy

GDPR

  • Self-service data export (art. 15/20) and account deletion (art. 17) from Settings
  • Data minimization: we only collect what the protocol needs
  • PII scrubbing in logging and error tracking
  • We maintain a processing register, DPIA, breach procedure and DPA inventory; summaries available on request
  • An ASVS-mapped security assessment report (scope, controls, findings and status) is available to customers on request
  • Details in our privacy policy

Data location & retention

  • Encrypted data is stored in Appwrite Cloud (US region), analytics in the EU
  • Account deletion removes all data after a 14-day grace period; invoices are retained for statutory bookkeeping periods
  • Data exports expire after 48 hours and at most 3 downloads

Responsible disclosure

Found a vulnerability? We want to hear about it before anyone else does. Email security@emberalis.com and give us reasonable time to fix the issue before public disclosure; we commit to acknowledging reports within 72 hours and will not pursue good-faith research. Machine-readable details live at /.well-known/security.txt.

Questions about security?

We answer every security and privacy question, in detail. That is the whole point of this page.

Contact us